HN user

icanhasfay

69 karma

Security. @icanhasfay

Posts13
Comments25
View on HN

Braintree | Software Engineer, Security | Chicago, San Francisco, New York City, Austin | Onsite | Fulltime

At Braintree we provide the global commerce tools people need to build businesses, accept payments, and enable commerce for their users. It’s the simplest way to get paid for your great ideas -- across any device, and through almost any payment method. Merchants in more than 40 countries worldwide can accept, split, and enable payments in more than 130 currencies using Braintree. And we’re here for you -- with stellar support, innovative concepts, and simple processes -- from your first dollar up past your billionth.

The Role:

The Security Engineer's role is to protect sensitive data and applications in high-scale systems that are growing rapidly. We need you to be heavily involved in keeping security top of mind as we look to power our customers' most important transactions.

Types of projects we work on:

  Working with product teams on the security of their new features
  Building custom tools to scale security responsibilities 
  Maintaining the authentication and encryption capabilities of a fast growing payments platform
What we look for in you:
  Solid programming foundation; expect to spend a significant amount of time writing code
  Working knowledge of one or several object-oriented or functional programming languages
  Working knowledge of applied cryptography and how to effectively develop appropriate cryptographic solutions
  Knowledge of PCI-DSS is a plus
  Previous wide-ranging experience in application security and policy development
  4+ years experience developing software with particular interest in keeping things safe and secure
For more details and to apply in, check: https://grnh.se/59656d971

Braintree | Software Engineer, Security | Chicago, San Francisco, New York City, Austin | Onsite | Fulltime At Braintree we provide the global commerce tools people need to build businesses, accept payments, and enable commerce for their users. It’s the simplest way to get paid for your great ideas -- across any device, and through almost any payment method.

Merchants in more than 40 countries worldwide can accept, split, and enable payments in more than 130 currencies using Braintree. And we’re here for you -- with stellar support, innovative concepts, and simple processes -- from your first dollar up past your billionth.

The Role:

The Security Engineer's role is to protect sensitive data and applications in high-scale systems that are growing rapidly. We need you to be heavily involved in keeping security top of mind as we look to power our customers' most important transactions.

Types of projects we work on:

  Working with product teams on the security of their new features
  Building custom tools to scale security responsibilities 
  Maintaining the authentication and encryption capabilities of a fast growing payments platform
What we look for in you:
  Solid programming foundation; expect to spend a significant amount of time writing code
  Working knowledge of one or several object-oriented or functional programming languages
  Working knowledge of applied cryptography and how to effectively develop appropriate cryptographic solutions
  Knowledge of PCI-DSS is a plus
  Previous wide-ranging experience in application security and policy development
  4+ years experience developing software with particular interest in keeping things safe and secure
For more details and to apply in, check: https://grnh.se/59656d971

Braintree | Software Engineer, Security | Chicago, San Francisco, New York City, Austin | Onsite | Fulltime

At Braintree we provide the global commerce tools people need to build businesses, accept payments, and enable commerce for their users. It’s the simplest way to get paid for your great ideas -- across any device, and through almost any payment method.

Merchants in more than 40 countries worldwide can accept, split, and enable payments in more than 130 currencies using Braintree. And we’re here for you -- with stellar support, innovative concepts, and simple processes -- from your first dollar up past your billionth.

The Role:

The Security Engineer's role is to protect sensitive data and applications in high-scale systems that are growing rapidly. We need you to be heavily involved in keeping security top of mind as we look to power our customers' most important transactions.

Types of projects we work on:

  Working with product teams on the security of their new features
  Building custom tools to scale security responsibilities 
  Maintaining the authentication and encryption capabilities of a fast growing payments platform
What we look for in you:
  Solid programming foundation; expect to spend a significant amount of time writing code
  Working knowledge of one or several object-oriented or functional programming languages
  Working knowledge of applied cryptography and how to effectively develop appropriate cryptographic solutions
  Knowledge of PCI-DSS is a plus
  Previous wide-ranging experience in application security and policy development
  4+ years experience developing software with particular interest in keeping things safe and secure
For more details and to apply in with us check: https://boards.greenhouse.io/braintree/jobs/1493945.

Hulu | Santa Monica, CA | Onsite | Full-time

Hulu is a premium streaming TV destination that seeks to captivate and connect viewers with the stories they love. We create amazing experiences that celebrate the best of entertainment and technology. We’re looking for great people who are passionate about redefining TV through innovation, unconventional thinking and embracing fun. It’s a mission that takes some serious smarts, intense curiosity and determination to be the best. Come be part of the team that’s powering play.

Hulu’s Information Security Team is seeking an Application Security Engineer as a new addition to the team. You can find the description for the role at the link below.

Application Security Engineer - https://www.hulu.com/jobs/positions/o4vg2fwr

And of course you can check out the rest of Hulu's open positions at https://www.hulu.com/jobs.

Hulu | Santa Monica, CA | Onsite | Full-time

Hulu is a premium streaming TV destination that seeks to captivate and connect viewers with the stories they love. We create amazing experiences that celebrate the best of entertainment and technology. We’re looking for great people who are passionate about redefining TV through innovation, unconventional thinking and embracing fun. It’s a mission that takes some serious smarts, intense curiosity and determination to be the best. Come be part of the team that’s powering play.

Hulu’s Information Security Team is seeking an Application Security Engineer and an Information Security Architect as new additions to the team. You can find the descriptions for the two roles at the links below.

Application Security Engineer - https://www.hulu.com/jobs/positions/o4vg2fwr Information Security Architect - https://www.hulu.com/jobs/positions/onlr4fwn

And of course you can check out the rest of Hulu's open positions at https://www.hulu.com/jobs.

Thanks for checking out the site. I can definitely attest to the difficulty in finding InfoSec positions on generic job boards as I was in the same position around a year and a half ago. As you mentioned, most of the positions on those job boards were either old postings, not actually relevant to InfoSec or posted through a recruitment agencies. This led me to practically writing regex's through the sites' filtering systems just to get back relevant postings. Having run through the problems firsthand, I wanted to try and solve these pain points by creating a community-driven job board for InfoSec positions, aka SecurityOverboard.

Just something itching me wrong about purposefully making a game excruciatingly difficult and then getting so emotionally affected by their reactions to that difficultly that you are distraught.

Have to disagree with a few points here.

"Hmmm, let me 'test' random website X for something that could cause a DoS"

The author was testing reflected XSS which is inherently client side, there should be no case of concern for DoS here.

"Building a "security portfolio" against websites is a stupid idea with some potentially huge negative consequences."

The author mentions Apple, Linkedin, Amazon and AT&T all of which have some type of vulnerability notification program. (See https://bugcrowd.com/list-of-bug-bounty-programs/ for a great list of programs) I would have to say that as long as the researcher was performing within the scope of the respective program, there should be no worry. I think it's the exact opposite of a stupid idea. Building out a portfolio within the scopes of the programs is a great way to build some security reputation.